Transcription

1 Proving Type Soundness of a Simply Typed ML-Like Language with References Olivier Boite and Catherine Dubois CEDRIC-IIE (CNAM), 18 allée Jean Rostand F EVRY, France Abstract. In this paper, we formalize in the Coq proof assistant an MLlike language with imperative features, a monomorphic type system, a reduction semantics, and the type soundness. We consider this language as an extension of Mini-ML, and emphasize the consequences on the definitions and the proofs due to this extension. 1 Introduction This paper reports on the machine-checked proof of the type soundness for a kernel of the ML language incorporating imperative features (references, assignments, sequences). Type soundness is a safety property that relates typing and evaluation : the evaluation of a well-typed program either loops, or terminates (by computing a value). Thus it never fails because of a type error or in other words, according to Milner,Well-typed programs do not go wrong. Different formal methods exist to describe the semantics of a language, we have chosen to use a reduction operational semantics (also called small-step semantics) as it is exemplified in [16]. Such a method allows to separate the different concepts and consequently provides more abstraction and modularity. Furthermore it describes the computation a step at a time, and so allows to express very fine properties about the computation. Some other works about the mechanical verification of language properties such as [12, 5] use also a reduction semantics. The formal development illustrated in this paper is done within the Coq proof assistant [6] and consequently can be seen as another formal piece that supplements the certification laid out in [5, 4] even if we consider here a monomorphic type system. As far as we are aware, among the different computer-verified proofs (e.g. [5, 4, 3, 12, 9, 15, 11, 13]), no publication mentions the computer-verified formalization and proof of type soundness for a fragment of ML mixing imperative and functional primitives. In [14], VanInwegen presents a formalization of Core Standard ML within HOL and by the way incorporates references. She has proved the type preservation property (it means that when the evaluation of a well-typed program terminates, it computes a value of the same type than the type of the program) for a good portion of the language. However this work is done with a big step semantics (based on an evaluation semantic relation).

2 70 O. Boite, C. Dubois Beyond this important and useful purpose, our work is the starting-point of the development of a formal framework (based on the Calculus of Inductive Constructions and Coq) that allows to define type systems àlamland to reason about them. Such a project requires at the same time the construction of formal components, a methodology and tools for composing and re-using formal pieces. At the present time, in order to reach this long term objective, we compare the formal development of the type soundness for Mini-ML, a language without imperative aspects and the formal development of the same property for Reference-ML, the same language with imperative features. Along this paper, we ll emphasize what have to be added in the proof or re-defined. We assume here familiarity with the Calculus of Inductive Constructions. We use version 6.3 of the Coq proof assistant. In order to make this paper more readable, we adopt a pseudo-coq syntax which differs slightly from the usual Coq syntax. Our paper provides the definitions of most concepts, the key lemmas but almost no proofs. The complete development is accessible on the Internet via soundness.tgz. The next section introduces a generic structure used to represent type environment and store. Section 3 describes the language. The semantics is exposed and formalized in the fourth section. Then, we present the typing in section 5. In the last section, we deal with the type soundness. 2 A Generic Table Static and dynamic semantics use structures to store information, for instance type environments that map free identifiers to types, or memories that map locations to values. So we present in this section the formalization of a generic structure table, which has two implicit parameters A and B, where A is the type of the keys, and B the type of the stored values. We define it as an inductive type with only one constructor intro table : its parameters are the domain of the table represented by a list of elements of type A, and a function from A to B. The type A is required to verify the decidability of the equality (predicate eq A dec). Inductive table : Set := intro_table : (list A) (A B) table. An object of type (table A B) is in fact a function whose domain is explicitly given, which allows us to use it as a partial function, or an association table. We define the operations of application, domain computing, adding of a new information in the table. We see a lot of advantages compared to a list of pairs : adding a new association doesn t create any redundancy, the computation of the domain and the application are got for free, as we can see below. Inductive apply_table : (table A B) A B Prop := intro_apply_table : l:a, dom:(list A), f:a B, l dom (apply_table (intro_table dom f) l (f l)).

3 Type Soundness of a Simply Typed ML-Like Language with References 71 The predicate (apply table t a b) stands for two properties : a dom(t) and t(a) =b, so the partiality of the function isn t a problem. The operation of adding is less simple, as we avoid redundancy. Definition add_table [a:a; b:b; t:(table A B)] : table := Cases t of (intro_table dom f) Cases a dom of _ (intro_table dom (λa :A.(Cases (eq_a_dec a a ) of _ b _ (f a ))) _ (intro_table (Cons a dom) (λa :A.(Cases (eq_a_dec a a ) of _ b _ (f a ))) The concrete definition of a table is never used in the formalization. We manipulate a table as an abstract data via several lemmas. The two most important of them follow, and are used to define a equivalence relation between tables. Lemma swap_table : A,B:Set, a,a,e:a, b,b,r:b, t:table, ~a=a (apply_table (add_table a b (add_table a b t)) e r) (apply_table (add_table a b (add_table a b t)) e r). Lemma add_add_table : A,B:Set, t:table, a,e:a, b,b,r:b, (apply_table (add_table a b t) e r) (apply_table (add_table a b (add_table a b t)) e r). The total Coq script for this structure with its lemmas overtakes 1000 lines. 3 The Language Reference-ML The first step to study a language is to formally define its syntax. However, it is not independent from the semantics. Actually, the semantics imposes to define two notions in addition to the language: memory locations and values. We first detail the syntax of the language. Then, in the second subsection, we discuss semantic extensions, and lastly we give the Coq translation. 3.1 Expressions We consider the following grammar of the expressions, in which we emphasize in a bold font the constructions of Reference-ML added to Mini-ML : e ::= c constant e ; e sequence x identifier while e do e loop ee application ref e reference creation fun xe abstraction!e look-up let x=e in e local definition e:=e assignment if e then e else e conditional c ::= n integer b boolean unit side-effect result

4 72 O. Boite, C. Dubois So Reference-ML is an extended λ-calculus which incorporates references and constructions to manipulate them. A reference is a memory cell containing a value. Its contains may be modified all along the program by using assignments. 3.2 Semantic Extensions We ve made the choice to work with a reduction semantics, also called Small-Step semantics. It focuses on each elementary step calculus, by rewriting expressions. With references, we have to take care of the memory state, which can change during the reduction process. For instance, the evaluation of an assignment e 1 := e 2 needs to evaluate e 1 to compute the location that is the address of the cell, whose contents in the memory has to be modified, and needs to evaluate e 2 to know which value to put in the memory. So, we have to explicitly manipulate locations in the reduction steps. The notion of location doesn t belong to the user s abstract syntax, but as we need it in the reduction process, we ve introduced it in the Coq definition of the language. Among the expressions, we have to distinguish the values. This notion is syntactic : a value is either a constant, either an abstraction (because the reduction strategy we use is a head reduction), or a location. 3.3 Coq Formalization In order to name the identifiers and the locations, we define two abstract types, respectively identifier and location. We assume the decidability of equality on both types, and we assume that one can always find a fresh location wrt a memory, that is to say one can exhibit a location l so that l denotes an address that does not appear in the memory. The language specification in Coq is obviously an inductive type : Inductive Constant : Set := Const_int : nat Constant Const_bool: bool Constant unit : Constant. Inductive expr : Set := Const : Constant expr Var : identifier expr Loc : location expr Fun : identifier expr expr Apply : expr expr expr Let_in: identifier expr expr expr If : expr expr expr expr While : expr expr expr Ref : expr expr Deref : expr expr Sequ : expr expr expr Assign: expr expr expr.

5 Type Soundness of a Simply Typed ML-Like Language with References 73 We define an object of type value as a pair composed of an expression e and a proof that e is a value. Inductive is_value : expr Prop := Cst_val : c:constant,(is_value (Const c)) Loc_val : l:location,(is_value (Loc l)) Fun_val : i:identifier, e:expr,(is_value (Fun i e)). Inductive value : Set := value_intro : e:expr,(is_value e) value. 3.4 From Mini-ML to Reference ML The extension of the language consists simply in adding new constructors in the inductive types expr and Constant : Loc, Sequ, While, Ref, Deref, Assign, and unit. So going from Mini-ML to Reference-ML produces supertypes (in the sense of object-oriented programming) : any Mini-ML expression is also a Reference-ML expression. The predicate is value is extended with the Loc val clause, but the definition of the type value is unchanged. 4 Reduction Semantics 4.1 Elementary Reduction and Reduction Strategy As a reduction semantics takes care of elementary steps of the computation, it s straightforward to explain the memory evolution during the reduction. A memory state is a finite mapping between locations and values. We require three operations on a memory m : dom(m) which computes the set of locations in the memory. m(l) which gives the value mapped to l in m. m (l, v) which maps l to v, and maps l to m(l )ifl dom(m) and l l. A configuration is an (expression/memory state)-pair, and the reduction relation is a transition relation between configurations. A reduction of the expression a 1 in the memory state m 1,intoa 2 in the memory state m 2 will be noted a 1 /m 1 a 2 /m 2. To define the reduction strategy, we ve adopted the technique which consists in defining an elementary reduction, also called ɛ-reduction, and the notion of reduction context, as proposed in [16]. We define the ɛ-reduction noted a 1 /m 1 ɛ a 2 /m 2 in Fig.1. In all the rules, v denotes a value. The two first rules corresponds to β-reductions, and a[v/x] denotes the substitution of x by v in a.

10 78 O. Boite, C. Dubois In this context, type environments contain not only type information about free identifiers, but also type information about locations. A type environment may be considered as a pair (Γ id,γ loc ): Γ id ::= Γ id (x : τ) Γ loc ::= Γ loc (l : τ) made up of a part Γ id relative to identifiers, and a part Γ loc relative to locations. Each part of the pair is an association table, and is specified in Coq by the generic structure table with the necessary parameters. This decomposition in the implementation makes easier the treatment. So Γ id, Γ loc, and Γ are respectively specified by Definition typ_env_ident := (table identifier type). Definition typ_env_loc := (table location type). Definition typ_env := typ_env_ident*typ_env_loc. We require two operations on type environments : the updating and the application, using the corresponding operations on tables : (Γ id,γ loc ) (k : τ) =(Γ id (k : τ),γ loc ) if k is an identifier =(Γ id,γ loc (k : τ)) if k is a location (Γ id,γ loc )(k) =Γ id (k) if k is an identifier = Γ loc (k) if k is a location To define the typing rules in Coq, we use an inductive predicate that contains a constructor per typing rule : Inductive type_of : typ_env expr type Prop := type_of_const : Γ :typ_env, c:constant (type_of Γ (Const c) (type_of_constant c))) type_of_var: Γ :typ_env_ident, x:identifier, τ:type Γ (x)=τ (type_of Γ (Var x) τ) Configuration Types Nothing ensures for a given location that the type of the value associated in the memory, and the type of this location in the type environment are the same. So, we define the notion of well-typed memory in an environment : the domain of the memory m and the domain of the locations part of the type environment Γ must be the same, and for each location l of this domain, if the type of l is τrefin the environment, then the value of l in the memory has the type τ in the environment. The Coq definition memory respects env follows this informal specification. To denote this relation informally, we write Γ m. Definition memory_respects_env [Γ :typ_env;m:memory] : Prop := Cases Γ of (Γ id,γ loc )

11 Type Soundness of a Simply Typed ML-Like Language with References 79 ( l:location, τ:type,v:expr,(apply_table m l v) (apply_table Γ loc l τ) (type_of Γ (value2expr v) τ)) dom(m)=dom(γ loc ) A configuration a/m is well-typed in an environment Γ,if a is well-typed in Γ and if m respects Γ. We define the typing of a configuration in Γ as the conjunction of the typing of the expression and the well-typing of the memory, both in Γ. Definition type_of_config [Γ :typ_env;c:configuration;τ:type] := Cases c of (e,m) (type_of Γ e τ) (memory_respects_env Γ m) 5.4 From Mini-ML to Reference ML The type algebra is extended with the type for references. Again we define a supertype. For the constructors common to Mini-ML and Reference-ML, the typing rules remains identical up to the re-definition of the operations and application on environments. The typing relation we want for Reference-ML has to type configurations - not only expressions. It means the memory has to respect the type environment, so we add this condition to the type relation as a conjunction. 6 Type Soundness Among the syntactically correct programs, we can distinguish three groups, those whose evaluation : terminates on a value indefinitely loops blocks (i.e. can t be reduced anymore but is not a value) The role of the typing is to limit the set of syntactically correct programs. We describe in this section the proof of the safety (or the soundness) of our type system. It means that the evaluation of a well-typed program, if it terminates, is a value. In other words, no type errors can appear during the computation, and the typing eliminates blocking-programs. We follow the structure of the paper-and-pencil proof given in [8], adapted to the monomorphic case. 6.1 The less typable Relation We define an ordering between configurations as follows : a 1 /m 1 is less typable than a 2 /m 2, written a 1 /m 1 a 2 /m 2, if for all environment Γ and all type τ, there exists an extension Γ of Γ so that (Γ a 1 : τ Γ m 1 )= (Γ a 2 : τ Γ m 2 )

13 Type Soundness of a Simply Typed ML-Like Language with References 81 Lemma 1 (Substitution lemma). if Γ e : τ and Γ (i, τ) e 1 : τ 1 then Γ e 1 [i\e] : τ 1 translated into Coq by : Lemma substitution_lemma: e1,e2,e:expr, i:identifier, Γ :typ_env, τ,τ 1:type, (subst_expr e1 i e e2) (type_of Γ (i : τ) e1 τ1) (type_of Γ e τ) (type_of Γ e2 τ1). This lemma is proved by induction on the expression e 1. The proof is easy, but requires to show that if an expression is well-typed in an environment then it is well-typed in an environment equivalent to the first one and furthermore the type is the same. Proposition 2 (Growing of ). if a 1 /m 1 a 2 /m 2, then E[a 1 ]/m 1 E[a 2 ]/m 2 Lemma less_typable_grows : E:context, c1,c2:configuration, (is_context E) (less_typable c1 c2) (less_typable (app_ctx E c1) (app_ctx E c2)). The proof is a structural induction on the predicate is context defining E. For each case, we give the extended environment Γ of Γ, given by the hypothesis (less typable c1 c2), to prove Γ E[e2] : τ with the condition Γ E[e1] : τ. 6.3 Normal Form Theorem The normal form theorem establishes that an expression in normal form, welltyped in an environment which types no identifier, is a value. We allow to have locations in the typing environment, because a location is a value, and to type a location we need the type information in the typing environment. If an expression is not in normal form, it means it can be reduced. That is to say, there exists a configuration that the relation red can reach. It is specified in Coq with : Definition is_reducible [c:configuration] := ( c :configuration. (red c c )). Definition config_is_value [c:configuration] := Cases c of (e,m) (is_value e) end. Theorem nf_typed_are_value: Γ loc :typ_env_loc, τ:type, c:configuration, (type_of_config (,Γ loc ) c τ) (is_reducible c) (config_is_value c).

14 82 O. Boite, C. Dubois The normal form theorem is a consequence of the progression lemma : Lemma 2 (Progression). If an environment types only locations, if a/m is well-typed in this environment, and if a is not a value, then a can be reduced. Lemma progression : Γ loc :typ_env_loc, c:configuration, τ:type, (type_of_config (,Γ loc ) c τ) (config_is_value c) (is_reducible c). We prove it by induction on a where c = a/m. When a is not a value, we explicitly give the expression in which a can reduce. In the case of a β-redex, the expression in which it reduces makes appear an expression resulting from a substitution. We have to prove that this expression really exists (because the substitution is not a total function). It is expressed by the following lemma, established by induction on the expression e. Lemma substitute_succeeds : e,e1:expr,i:identifier, τ:type, Γ loc :typ_env_loc, (type_of (,Γ loc ) e1 τ) (is_value e1) ( e :expr. (subst_expr e i e1 e )). 6.4 Strong Type Soundness The theorem Subject Reduction ensures types are preserved across a reduction step. The theorem of the normal form ensures a well-typed program in the initial environment, which can t reduce anymore, is a value. As a consequence of this two previous theorems, we obtain the type soundness : the evaluation of a term of type τ doesn t block, but furthermore if it terminates, we obtain a value of type τ. It s the strong version of the type soundness. Formally, we have to define the reflexive and transitive closure of the reduction relation red star : Inductive red_star : configuration configuration Prop:= red_0 : sn:configuration,(red_star sn sn) red_n : sn,s0,s :configuration, (red s0 s ) (red_star s sn) (red_star s0 sn). The type soundness is specified as follows : Theorem type_safe : a:expr, τ:type, c :configuration, (red_star (a, ) c ) (type_of_config (, ) (a, ) τ) (is_reductible c ) (config_is_value c ) ( env:typ_env (type_of_config env s t)) This theorem is proved by induction on the length of the reduction. In the case corresponding to red 0, we apply the normal form theorem. In the induction case red n, the property follows from the induction hypothesis and the Subject Reduction theorem.

15 Type Soundness of a Simply Typed ML-Like Language with References From Mini-ML to Reference ML In Mini-ML, a 1 a 2 means if a 1 has the type τ in an environment Γ, then a 2 has the type τ in Γ. The relation of Reference-ML is an extension of that of Mini- ML, if we re-define type of by type of config and if we accept to extend the type environment to type the second configuration. It is a conservative extension, because the extension of an environment concerns the location part, and there isn t location part in Mini-ML. The proofs of Type preservation by ɛ-reduction, substitution lemma, growing of, progression and substitute succeeds, nf typed are values are inductive proofs. All the proof cases we had in Mini-ML are quite the same in Reference-ML, and of course, new cases are treated. The proof of Subject Reduction, as it uses the previous propositions - is exactly the same in both languages. Our final theorem, type-safe, concludes (config is value c ). It is the same theorem as in Mini-ML if we re-define config is value, and the proof (by induction) has the same cases as Mini-ML plus its own cases. 7 Conclusion This work has two interests. The first is that, as far as we know, it is the first machine-ckecking of the type-soundness of an ML-like language with references in a reduction semantics. The second is that it focuses on the impact on the definitions and the proofs when the language is extended. We can find in many papers where a language is extended the proof is similar to the previous case.... We wanted to quantify this fact. Our experience is that the machine-checking verifies this, if we take care to extend and re-define the good notions. In our study, our Coq script rises from 2100 to 3700 lines (both including 1000 lines for the package on the generic table). The paper tries to trace the different supertypes, extensions and redefinitions that the new features introduce. In a future work, we ll extend Reference-ML in another way, with polymorphism, or object for example. Paper-pencil proofs exist for many years. All have proved that some notions are exactly the same, others are extended, others are re-defined. Indeed, our final aim is to define a formal method to specify the extension L i+1 of a language L i, and to use the proofs of the properties of L i to show those of L i+1. This method wouldn t be valid in a non-conservative extension. Several works [1], [2], [10], deal with proof reuse in the context of inductive types, it would be very interesting to try to merge them with our concerns and develop ad hoc tools. Acknowledgements We thank Véronique Viguié Donzeau-Gouge for the useful discussions we had with her. References [1] G. Barthe and O. Pons. Type Isomorphisms and Proof Reuse in Dependent Type Theory. In F. Honsell and M. Miculan, editors, Proceedings of FOSSACS 01,

CHAPTER 7 GENERAL PROOF SYSTEMS 1 Introduction Proof systems are built to prove statements. They can be thought as an inference machine with special statements, called provable statements, or sometimes

Extraction of certified programs with effects from proofs with monadic types in Coq Marino Miculan 1 and Marco Paviotti 2 1 Dept. of Mathematics and Computer Science, University of Udine, Italy 2 IT University

Automated Theorem Proving - summary of lecture 1 1 Introduction Automated Theorem Proving (ATP) deals with the development of computer programs that show that some statement is a logical consequence of

WHAT ARE MATHEMATICAL PROOFS AND WHY THEY ARE IMPORTANT? introduction Many students seem to have trouble with the notion of a mathematical proof. People that come to a course like Math 216, who certainly

Overview Elements of Programming Languages Lecture 12: Object-oriented functional programming James Cheney University of Edinburgh November 6, 2015 We ve now covered: basics of functional and imperative

Predicate Logic Review UC Berkeley, Philosophy 142, Spring 2016 John MacFarlane 1 Grammar A term is an individual constant or a variable. An individual constant is a lowercase letter from the beginning

Chapter II. Controlling Cars on a Bridge 1 Introduction The intent of this chapter is to introduce a complete example of a small system development. During this development, you will be made aware of the

Moving from CS 61A Scheme to CS 61B Java Introduction Java is an object-oriented language. This document describes some of the differences between object-oriented programming in Scheme (which we hope you

Termination Checking: Comparing Structural Recursion and Sized Types by Examples David Thibodeau Decemer 3, 2011 Abstract Termination is an important property for programs and is necessary for formal proofs

Applied Type System (Extended Abstract) Hongwei Xi Boston University Abstract. The framework Pure Type System (PTS) offers a simple and general approach to designing and formalizing type systems. However,

A Propositional Dynamic Logic for CCS Programs Mario R. F. Benevides and L. Menasché Schechter {mario,luis}@cos.ufrj.br Abstract This work presents a Propositional Dynamic Logic in which the programs are

Using the Computer to Prove the Correctness of Programs Bengt Nordström bengt@cs.chalmers.se ChungAng University on leave from Chalmers University, Göteborg, Sweden Using the Computer to Prove the Correctness

Mathematics for Computer Science/Software Engineering Notes for the course MSM1F3 Dr. R. A. Wilson October 1996 Chapter 1 Logic Lecture no. 1. We introduce the concept of a proposition, which is a statement

Mathematical Reasoning in Software Engineering Education Peter B. Henderson Butler University Introduction Engineering is a bridge between science and mathematics, and the technological needs of mankind.

Integration of Application Business Logic and Business Rules with DSL and AOP Bogumiła Hnatkowska and Krzysztof Kasprzyk Wroclaw University of Technology, Wyb. Wyspianskiego 27 50-370 Wroclaw, Poland Bogumila.Hnatkowska@pwr.wroc.pl

15-150 Lecture 11: Tail Recursion; Continuations Lecture by Dan Licata February 21, 2011 In this lecture we will discuss space usage: analyzing the memory it takes your program to run tail calls and tail

The Classes P and NP We now shift gears slightly and restrict our attention to the examination of two families of problems which are very important to computer scientists. These families constitute the

Types, Polymorphism, and Type Reconstruction Sources This material is based on the following sources: Pierce, B.C., Types and Programming Languages. MIT Press, 2002. Kanellakis, P.C., Mairson, H.G. and

Midlands Graduate chool in the Foundations of omputer cience Operational emantics, Abstract Machines, and orrectness Roy L. role University of Leicester, 8th to 12th April 2006 University of Nottingham,

An Innocent Investigation D. Joyce, Clark University January 2006 The beginning. Have you ever wondered why every number is either even or odd? I don t mean to ask if you ever wondered whether every number

Programming Languages Programming languages bridge the gap between people and machines; for that matter, they also bridge the gap among people who would like to share algorithms in a way that immediately

Lecture 1: Induction and the Natural numbers Math 1a is a somewhat unusual course. It is a proof-based treatment of Calculus, for all of you who have already demonstrated a strong grounding in Calculus

Type Systems Luca Cardelli Microsoft Research 1 Introduction The fundamental purpose of a type system is to prevent the occurrence of execution errors during the running of a program. This informal statement

CST.98.5.1 COMPUTER SCIENCE TRIPOS Part IB Wednesday 3 June 1998 1.30 to 4.30 Paper 5 Answer five questions. No more than two questions from any one section are to be answered. Submit the answers in five

ICMS, 26 May 2007 1/17 Bindings, mobility of bindings, and the -quantifier Dale Miller, INRIA-Saclay and LIX, École Polytechnique This talk is based on papers with Tiu in LICS2003 & ACM ToCL, and experience

MAT2400 Analysis I A brief introduction to proofs, sets, and functions In Analysis I there is a lot of manipulations with sets and functions. It is probably also the first course where you have to take

Static Program Transformations for Efficient Software Model Checking Shobha Vasudevan Jacob Abraham The University of Texas at Austin Dependable Systems Large and complex systems Software faults are major

1 15 th International School on Foundations of Software Security and Design August 31 st, 2015, Bertinoro Certifying the Security of Android Applications with Cassandra Steffen Lortz, Heiko Mantel, David

+a 1. R In this and the next section we are going to study the properties of sequences of real numbers. Definition 1.1. (Sequence) A sequence is a function with domain N. Example 1.2. A sequence of real

M3210 Supplemental Notes: Basic Logic Concepts In this course we will examine statements about mathematical concepts and relationships between these concepts (definitions, theorems). We will also consider

Chapter 3 Cartesian Products and Relations The material in this chapter is the first real encounter with abstraction. Relations are very general thing they are a special type of subset. After introducing

PROGRAM LOGICS FOR CERTIFIED COMPILERS Separation logic is the twenty-first-century variant of Hoare logic that permits verification of pointer-manipulating programs. This book covers practical and theoretical